IEC 62443-3-3 System Security Requirements
IEC 62443-3-3 specifies the technical security requirements an industrial automation and control system must meet for each security level, organised under the seven IEC 62443 foundational requirements.
IEC 62443-3-3, System security requirements and security levels, specifies the technical security capabilities that an industrial control system must provide to meet each security level. Requirements are organised under the seven foundational requirements and expressed as system requirements, with requirement enhancements that are added at higher levels. Together they define what a system needs at SL 1, SL 2, SL 3 and SL 4.
Asset owners reference IEC 62443-3-3 in specifications to state the capabilities they expect from an integrated control system, and integrators use it to design zones and select products. Requirement areas include user and device authentication, authorisation enforcement, software and information integrity, audit logging, network segmentation, denial-of-service protection and control system backup and recovery. Control system suppliers can have systems certified against the standard, for example through the ISASecure System Security Assurance scheme.
IEC 62443-3-3 describes capabilities, not how they are configured in a given plant, so achieving a security level also depends on deployment, procedures and maintenance. Legacy components that lack required capabilities may need compensating countermeasures at the zone or conduit level. The component-level counterpart is IEC 62443-4-2, which allocates similar requirements to individual software applications, embedded devices, host devices and network devices.
Key points
- Defines system requirements and enhancements for security levels 1 to 4
- Organised under the seven foundational requirements of IEC 62443
- Used in specifications, system design and system certification
- Component-level requirements are covered by IEC 62443-4-2
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- IEC 62443 Foundational Requirements (FR)OT & Industrial Cybersecurity
- IEC 62443 Security Levels (SL)OT & Industrial Cybersecurity
- IEC 62443-4-2 Component Security RequirementsOT & Industrial Cybersecurity
- ISASecure CertificationOT & Industrial Cybersecurity
- IEC 62443-3-2 Security Risk AssessmentOT & Industrial Cybersecurity